PT-2007-1171 · Novell · Novell Edirectory

Publicado

2007-04-30

·

Atualizado

2017-07-20

·

CVE-2006-4520

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Novell eDirectory versions prior to 8.7.3 SP9 Novell eDirectory versions 8.8.x prior to 8.8.1 FTF2
Description: The issue is related to the handling of NCP fragments with a negative length by ncp in Novell eDirectory. This improper handling allows remote attackers to cause a denial of service, resulting in a daemon crash when the heap is written to a log file.
Recommendations: For Novell eDirectory versions prior to 8.7.3 SP9, update to version 8.7.3 SP9 or later. For Novell eDirectory versions 8.8.x prior to 8.8.1 FTF2, update to version 8.8.1 FTF2 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4520

Produtos afetados

Novell Edirectory